name: CI on: # No `push` trigger, so nothing re-validates a merge commit on main — an accepted infra-load tradeoff mara signed off on, not an oversight. pull_request: branches: ["**"] # Lets `hive-forge ci-rerun` re-trigger CI via workflow-dispatch API workflow_dispatch: jobs: check: name: nix flake check if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} # 30 min is well above a cold-cache rebuild (~15 min observed) and well # under the runner's 3h cap timeout-minutes: 30 steps: - uses: actions/checkout@v3 - name: check run: nix flake check tracker-tags: name: tracker-tag lint if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint run: sh scripts/check-issue-refs.sh comment-blocks: name: comment-block lint if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint run: sh scripts/check-comment-blocks.sh doc-refs: name: doc-pointer lint if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint run: sh scripts/check-doc-refs.sh attribution-trailers: name: attribution-trailer lint if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 5 steps: - uses: actions/checkout@v3 with: fetch-depth: 0 - name: lint run: sh scripts/check-attribution-trailers.sh dashboard-descriptions: name: dashboard-description lint if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint # jq isn't a project dependency elsewhere in this repo — same # nix-shell-for-one-tool shape the vale/shellcheck jobs above use. run: nix shell nixpkgs#jq --command sh scripts/check-dashboard-descriptions.sh shellcheck: name: shellcheck if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 10 steps: - uses: actions/checkout@v3 - name: lint # By shebang, not a `*.sh` glob — scripts/pre-push has no suffix. run: | files=$(grep -lE '^#!.*/(env[[:space:]]+)?(ba)?sh([[:space:]]|$)' scripts/* 2>/dev/null) if [ -z "$files" ]; then echo "no shell files discovered under scripts/ — check the shebang pattern" >&2 exit 1 fi echo "$files" | xargs nix develop -c shellcheck -S warning prose-lint: name: prose lint (vale) if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint # Styles are fetched fresh from Vale Package Hub each run (not vendored). # Not wired into branch protection — see prose-lint-errors below for the # error-only slice that is. run: XDG_DATA_HOME="$PWD/.vale-data" nix shell nixpkgs#vale --command sh -c 'vale sync && vale docs' prose-lint-errors: name: prose lint (vale, errors) if: vars.PUBLIC_FORGE != 'true' runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }} timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint # Error-level-only slice. Split out so this job alone can be a required # check without blocking merges on the warning/suggestion backlog. run: XDG_DATA_HOME="$PWD/.vale-data" nix shell nixpkgs#vale --command sh -c 'vale sync && vale --minAlertLevel=error docs'